Register of Processing Activities (ROPA)
Version 2026-06-19-v3-es. Last reviewed 19 June 2026.
Article 30 GDPR requires the controller to maintain a register of every processing activity. The AEPD expects this register to be available on request; we publish the customer-facing summary here. The internal version, including the names of staff with access and the technical and organisational security measures, is held by the Data Protection Officer and can be inspected on lawful demand by the AEPD.
Controller
NEMRAC Consulting S.L. (T4G Impact), Spain TIN B44624740, Spain. Sole controller; no joint-controllership. Data Protection Officer: dpo@t4glab.com.
Processing activities
| Activity | Categories of data | Lawful basis | Recipients / sub-processors | Transfers outside EEA | Retention |
|---|---|---|---|---|---|
| Account creation and authentication | Email, full name, password hash, federated IDs | Art. 6(1)(b) GDPR — performance of a contract | Amazon Cognito (AWS EMEA SARL) | None — processed in eu-west-1 | 24 months from last sign-in, then delete or anonymise |
| Roster profile | Sectors, fields, salary expectations, availability, notes | Art. 6(1)(a) — consent (visibility on the roster) | Internal admins; AWS DynamoDB | None | Together with the account |
| CV storage | CV document, frequently including Art. 9 GDPR special-category data (health, religion, ethnicity, union, sexual orientation) | Art. 6(1)(b) for the file; Art. 9(2)(a) explicit consent for any Art. 9 content | AWS S3 (EU-encrypted with KMS) | None | Active candidate: 12 months from upload with annual re-consent. Unsuccessful candidate: 12 months from rejection. Withdrawn: 30 days max. See privacy §6. |
| AI-assisted CV parsing | CV file → structured enrichment fields | Art. 6(1)(f) — legitimate interest in a usable roster; Art. 9(2)(a) for any special-category content | Anthropic PBC (Claude Sonnet 4.6) | United States (Anthropic). EU–US Data Privacy Framework; fallback SCC + TIA | Tied to the source CV — deleted with it |
| Federated sign-in | Email and federated subject identifier from Google | Art. 6(1)(b) — performance of contract | Google LLC | United States. EU–US Data Privacy Framework + Google Model Clauses | Together with the account |
| Marketing communications | Email, opt-in flag, opt-in timestamp | Art. 6(1)(a) GDPR + Art. 21 LSSI (Spain) | Internal admins | None | While opted in; deleted within 30 days of withdrawal |
| Consent audit (Art. 7 GDPR) | Profile id, email, consent kind, action, timestamp, policy version | Art. 6(1)(c) + Art. 7(1) — proof obligation | Internal admins; AWS DynamoDB | None | 6 years from the event under Art. 17(3)(e) (defence of legal claims); survives erasure of the underlying profile |
| Admin review audit (CvAccessLog) | Profile id, admin email, action, timestamp | Art. 6(1)(c); EU AI Act Art. 26(6) deployer log-retention duty | Internal admins | None | 6 months minimum |
| Security and abuse prevention | IP, user-agent, request path, error logs | Art. 6(1)(f) — legitimate interest in service integrity | AWS CloudWatch (EU) | None | 90 days |
Special-category data (Art. 9 GDPR)
We do not intentionally collect Art. 9 data. We acknowledge that CVs frequently include such content. We rely on the explicit consent of the candidate (Art. 9(2)(a)) given at the point of upload, with the right to refuse without losing access to the Service.
Children
The Service is for adults 18+. We do not process the personal data of minors. Spain’s LOPDGDD Art. 7 sets the digital-consent age at 14, which is lower than the GDPR default of 16 — we do not rely on the LOPDGDD lower threshold and instead apply a strict 18+ floor.
Security measures (summary)
- TLS in transit; AWS KMS encryption at rest.
- Row-level authorisation: candidates can only read their own row; admins are gated by a Cognito ADMIN group with mandatory MFA.
- Every admin action against a candidate’s data is recorded in
CvAccessLog. - Anthropic transfer additionally covered by an internal Transfer Impact Assessment, reviewed at least annually.
- Restricted profiles (Art. 18 GDPR) are excluded at code level from matching and from enrichment reruns.
Contact
DPO: dpo@t4glab.com.
Privacy enquiries: privacy@t4glab.com.
Lead supervisory authority: AEPD.